Live data from Hacker News

Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

theregister.co.uk

101–110 of 216 posts

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#101

Brute forcing weak passwords? Someone is doing something horribly wrong here on several levels. At the very least anything online of any importance should have rate limits if not locking for repeated password attempts. For servers themselves allowing password logins is inexcusably bad. It is considered a bit overzealous by most but I believe that passwords should have been done away with a long time ago in favor of c…

I suspect some places still only use passwords for server logins because they can simply use active directory for user management and then have servers use ad/ldap for credential checking. I think businesses with critical infrastructure should use hardware keys (e.g. yubikeys) to provide at least one of the factors needed to log in to a server. Using a yubikey as an authentication key for ssh is not that difficult an…

> This requires the enterprise to run up to date browser however.

Why is this so hard?!? I agree with you, but this sentence rang so true it was sad. I've been forced to work with/around unbelievably out-of-date browsers in order to install current firmware updates on systems at almost every place I've worked.

/rant

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#103
post #78
post #73

Earlier quoted context omitted.

How did we come to this imbalance?

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

Truly free people are free to keep all the secrets they want.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#104
Ah, The Register lifting another story from another news outlet.

The original report came from NBC: https://www.nbcnews.com/politics/national-security/iranian-b...

Which The Register didn't bother to credit. I swear, this site is now no worse than an Indian blog. Every site online credited NBC except these "journalism experts" (to be red clickbait-loving, content thieving d-bags)

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#105

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

It’s absolutely reasonable to be critical of any accusations that “Iran did it” or any other nation that the US considers enemies. Didn’t our security ministers claim North Korea was behind the Sony hacks when Obama was in office? We were never given any proof, so it’s impossible to verify... When you consider the way we lie on international affairs, all statements our government makes must be considered suspect. Thi…

> We were never given any proof, so it’s impossible to verify...

Bullshit.

https://www.nytimes.com/2015/01/19/world/asia/nsa-tapped-int...

https://www.recode.net/2015/4/21/11561700/sony-hack-was-not-...

https://www.symantec.com/connect/blogs/collaborative-operati...

https://www.nytimes.com/2018/09/06/us/politics/north-korea-s...

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#106
post #88
post #82

Earlier quoted context omitted.

Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory. This is either an insider joke or a jump back to 2004.

this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...

Well, its better to get some wordpress hacked, than it is to have a server onprem get pwned and used as a inadvertent bastion to your internal network.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#107
post #78

Earlier quoted context omitted.

State secrecy being used as an excuse for violence. A truly free people keep no secrets.

Truly free people are free to keep all the secrets they want.

.. and they will forever be ruled by them, so: not free.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#108

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

Neither the US government nor Citrix have implicated Iran. Resecurity came out of the woodwork contacting media companies about its supposed research after Citrix posted a brief statement explaining the FBI had notified it of a breach.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#109

The evidence that points to Iran comes from a company named, Resecurity. But there are some odd stuff about this company. 1 - their CEO has no real linkedIn history [1] 2 - they revenue and employment went off the chart just in 2 quarters [2] 3 - very unclear how they came to this assessment. Especially now that US government is looking for excuses (real or fabricated) to make a case for war with Iran, I look at thes…

I've looked over their website and I'm confused about what they actually do. They are "trusted by leading Fortune 500 corporations" apparently (with logos for Microsoft and Amazon), but the entire "Interested in our solutions" section is a sign up form. What am I signing up for? It's unusual for a company to barely try to promote their products.

Yes, it makes you wonder, how does a small company pop into existence straight into class-A office space in downtown LA, and within the span of what? two years? claims to have done business with a dozen or so heavyweight companies. And what is their web presence? Vague, inscrutable C-suite-speak about security, and one blockbuster claim in the Citrix break.

At some point, Occam's razor will favor that this company is having its strings pulled by some larger entity that doesn't want to be revealed.

Re: Hackers ransack Citrix, make off with 6TB+ of emails, biz docs, secrets

#110
post #19

Earlier quoted context omitted.

I work with digitisation in the public sector of Denmark. We’ve digitised our elections, but we’ve digitised the part that makes sense, the registration you do before you’re handed you ballot. In the old days, we used to have big books where you’d get crossed off after you were identified. This naturally takes a lot of time, so today we print a little bar code on the piece of paper that we mail every adult citizen at…

In Australia we have the staff still ruling us off in the electoral role. That usually takes a minute or less. The entire voting process (including queuing) depends upon the popularity of the individual voting booth and time of day, but is usually less than 10 minutes. This may be because there are an adequate number of booths and trained staff.But it is also because of compulsory voting. The highly likely attendance…

As a Dane, our palementary elections gets about 86-90% participations, and not having voting mandatory means you get an effective signal for how the population feels by how well they attend.

We are due for a new election before july, so I will probably just save the queue and vote by mail, if I elect to vote at all.

Post reply on HN